# CVE-2021-35342 - useradm incorrect access control vulnerability | Mender

**URL:** <https://hub.mender.io/t/cve-2021-35342-useradm-incorrect-access-control-vulnerability-mender/4024>\
**Category:** Announcements\
**Created:** [August 23, 2021, 10:21am UTC](https://hub.mender.io/t/cve-2021-35342-useradm-incorrect-access-control-vulnerability-mender/4024 "2021-08-23T10:21:48Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![farshadt](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@farshadt](https://hub.mender.io/u/farshadt)\
**Post date:** [August 23, 2021, 10:21am UTC](https://hub.mender.io/t/cve-2021-35342-useradm-incorrect-access-control-vulnerability-mender/4024/1 "2021-08-23T10:21:48Z")

</div>

We recently discovered a vulnerability in Mender Enterprise, and we have now fixed it.

When the useradm service was configured to cache the user's JWT token verification, the token wasn't fully invalidated on log out, making it possible to issue new API calls to the backend despite being logged out. The security issue affects Mender Enterprise 2.6.0 and 2.7.0, and we fixed it in Mender Enterprise 2.6.1 and 2.7.1. Open-source versions of Mender are not affected, as they do not include the caching features.

* * *
This is a companion discussion topic for the original entry at [https://mender.io/blog/cve-2021-35342-useradm-logout-vulnerabililty](https://mender.io/blog/cve-2021-35342-useradm-logout-vulnerabililty)
